K3ysTr0K3R
61 exploits
Active since Jan 2009
webcamXP <5.3.2.410 - Path Traversal
2 stars
Apache mod_cgi Bash Environment Variable Code Injection (Shellshock)
NextGen Healthcare Mirth Connect <4.4.1 - RCE
SpaceLogic C-Bus Home Controller < 1.31.460 - OS Command Injection
Apache Spark UI - Privilege Escalation
Revive Adserver <5.1.0 - Open Redirect
Ericsson Drutt Mobile Service Delivery Platform 4,5,6 Path Traversal via Dot Dot Encoded Slash
1 stars
Apache ActiveMQ Broker, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
CVSS 8.8
Geoserver unauthenticated Remote Code Execution
CVSS 9.8
Oracle MySQL 5.1.x < 5.1.63, 5.5.x < 5.5.24, 5.6.x < 5.6.6 - Authentication Bypass via Repeated Failed Authentication
libssh Authentication Bypass Scanner
CVSS 9.1
Apache Tomcat 7.0.0-7.0.79 - Unauthenticated Remote Code Execution via JSP Upload
CVSS 8.1
gradio-app/gradio - Info Disclosure
CVSS 7.5
FreePBX 15.0-15.0.65 - Unauthenticated Authentication Bypass and Remote Code Execution
CVSS 9.8
PHP < 5.3.12 and 5.4.x < 5.4.2 - Remote Code Execution via CGI Query String
CVSS 9.8
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
CVSS 9.8
ACME mini-httpd < 1.30 - Unauthenticated Arbitrary File Read
CVSS 6.5
Nacos < 1.4.1 - Authentication Bypass via User-Agent Spoofing
CVSS 8.6
GitLab 11.9.0-13.8.7 - Unauthenticated Remote Code Execution via ExifTool Image Parsing
CVSS 10.0
Redis Lua Sandbox Escape
CVSS 10.0
Xdebug < 2.5.5 - Unauthenticated OS Command Injection via Remote Debugger Interface
GNU Inetutils Telnet Authentication Bypass Exploit CVE-2026-24061
CVSS 9.8
Investi <= 1.0.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'maximum-num-years' Shortcode Attribute
CVSS 6.4
xfrm: esp: avoid in-place decrypt on shared skb frags
CVSS 8.8
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
CVSS 7.8